Yahoo Music Jukebox ActiveX Control Buffer Overflow Attack

Strike ID:
G08-3hd01
CVSS:
4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
False Positive:
f
Variants:
1
Year:
2008

Description

This strike exploits a buffer overflow vulnerability in the MediaGrid ActiveX control utilized by Yahoo! Music Jukebox. These vulnerabilities are caused due to boundary errors within the Yahoo! Music Jukebox ActiveX Control. A remote attack can exploit these vulnerabilities by enticing the target user to open a crafted webpage, potentially causing arbitrary code to be injected and executed in the security context of the current user. An attack targeting this vulnerability can result in the injection and execution of arbitrary code. If code execution is successful, the behaviour of the target will depend on the intention of the attacker. Any injected code will be executed within the security context of the currently logged in user. In the case of an unsuccessful code execution, Internet Explorer may terminate abnormally.

CVE

References

Bid